Network Activity Signatures for Encrypted Session Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of network encryption makes it difficult to detect user activities in wireless communication networks, necessitating a more efficient method to infer events during application sessions.

Innovation Solution

A computing system generates network activity signatures from transaction data and applies machine learning and pattern recognition to infer events, using a database of signatures to improve inference accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network encryption is used to secure communication, then security and privacy are improved, but detectability of user activities deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser activity detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces network activity signatures as an intermediary representation that captures user activity patterns without requiring direct decryption of encrypted traffic. These signatures act as mediators between the encrypted network traffic and the analysis system, enabling inference of user activities through metadata and behavioral patterns rather than direct content inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical detection methods (packet inspection, deep packet buffering) with machine learning-based inference systems. Instead of directly analyzing encrypted traffic contents, the system uses ML models to predict user activities based on network activity signatures, substituting complex decryption mechanisms with intelligent pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If traditional packet inspection methods are used to analyze web traffic, then direct detection capability is improved, but effectiveness in encrypted environments deteriorates

Engineering Contradiction:
Improveweb traffic analysis capabilityVSAvoiddetection effectiveness in encrypted networks
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent creates a virtual copy of network activity through signatures that replicate the essential characteristics of user behaviors without copying actual encrypted traffic contents. These signatures capture the behavioral essence of activities (browsing patterns, interaction sequences) while remaining independent of the encrypted data itself, enabling analysis without compromising encryption.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the analysis approach by changing from analyzing raw packet parameters (which are inaccessible in encrypted traffic) to analyzing derived signature parameters (behavioral patterns, temporal sequences, interaction graphs). This parameter transformation enables effective analysis of encrypted traffic by working with metadata and inferred characteristics rather than raw data.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If machine learning models are trained on diverse network activity signatures, then inference accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveevent inference accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex task of network activity analysis into distinct modular components: signature generation module, signature storage database, and machine learning inference module. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by dividing the complex analysis function into manageable, specialized units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-generating and storing network activity signatures in a database during normal network operation. These signatures are prepared in advance and stored for later use by the machine learning models, eliminating the need for real-time complex analysis and reducing the computational burden during actual inference operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11310325B2Application session event inference from network activity
Publication Date: 2022.04.19 T MOBILE US INC
  • US11310325B2 patent drawing
  • US11310325B2 patent drawing
  • US11310325B2 patent drawing

AI summary

A computing system may automatically infer one or more events that occur during an application session involving activity on a network, such as the Internet. Such an application session may be interactions with, for example, social networking websites, banking websites, news websites, and so on. Events are any of a number of activities or transactions that may occur during the application session. The computing system may automatically infer an event by gathering network transaction data for network transactions performed by one or more client devices of a wireless communication network. The computing system may generate a network activity signature based, at least in part, on the network transaction data and apply pattern recognition and/or machine learning to the network activity signature to infer events associated with the network activity signature.